id: PYSEC-2025-146 published: "2025-08-07T16:15:30.150Z" modified: "2025-08-14T20:00:57.547Z" withdrawn: "2026-06-10T11:00:00Z" aliases: - CVE-2025-44779 details: An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull. affected: - package: name: ollama ecosystem: PyPI purl: pkg:pypi/ollama ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: 0.1.33-NA ecosystem_specific: {} references: - type: WEB url: https://a1batr0ss.top/2025/03/17/Ollama-arbitrary-file-deletion-vulnerability/ - type: WEB url: https://a1batr0ss.top/2025/08/06/CVE-2025-44779-Ollama-arbitrary-file-deletion/ - type: PACKAGE url: https://github.com/ollama/ollama severity: - type: CVSS_V3 score: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H